Open in app
Home
Notifications
Lists
Stories

Write
Ayoub FATHI
Ayoub FATHI

Home

Published in InfoSec Write-ups

·Apr 15, 2019

How I gained access to revenue and traffic data of thousands of Shopify stores

Leveraging reconnaissance tricks to exploit a vulnerability that allows accessing Revenue and Traffic data of thousands of Shopify stores — Index Introduction Almost vulnerable Getting da wordlist A Fail The new approach The exploit Timeline Takeaway Permission to write a blog post was given by Shopify prior to this public disclosure 1. Introduction About one year ago when I was hacking on Shopify program, I had to set a few alerts to get…

Bug Bounty

11 min read

Unveiling revenue & traffic data of thousands of Shopify stores
Unveiling revenue & traffic data of thousands of Shopify stores
Ayoub FATHI

Ayoub FATHI

Security Engineering

Following
  • @boblord

    @boblord

  • Sam Houston

    Sam Houston

  • Akash Mahajan

    Akash Mahajan

  • David Sacks

    David Sacks

  • Detectify

    Detectify

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Knowable